Skip to main content
NetApp Knowledgebase

Cannot delete expiring KMIP client certificate in ONTAP to install new certificate

Views:
51
Visibility:
Public
Votes:
0
Category:
ontap-9
Specialty:
encryption
Last Updated:

Applies to

  • ONTAP 9.5
  • ONTAP 9.6

Issue

  • User wants to delete expiring KMIP client certificate and install a new one.
  • Deleting current KMIP client certificate fails with the following error:
    ::*>security certificate delete -vserver vs1 -common-name prod1 -ca "cert1" -type client -serial xxxxxxxxxxxxxxxxxxxxx

    Error: command failed on vserver "vs1" common-name "prod1" ca "cert1" type "client" subtype "kmip-cert": The certificate could not be removed due to the following conflicts:

    Cannot remove certificate with subtype "kmip-cert" while external keymanager is configured.

 

CUSTOMER EXCLUSIVE CONTENT

Registered NetApp customers get unlimited access to our dynamic Knowledge Base.

New authoritative content is published and updated each day by our team of experts.

Current Customer or Partner?

Sign In for unlimited access

New to NetApp?

Learn more about our award-winning Support